IndustrialCyber

Booz Allen: AI models approaching autonomous cyberattack capability as critical infrastructure response windows narrow


New research from Booz Allen found that testing of 18 U.S. and Chinese frontier AI models revealed that AI (artificial intelligence) is nearing the ability to conduct cyberattacks autonomously, raising concerns for critical infrastructure operators facing increasingly narrow windows to detect and respond to intrusions. The company’s Cyber Weapon Index found that one model, Anthropic’s Claude Mythos, autonomously completed full cyber kill chain in a production-grade enterprise network, including gaining administrator-level access using a stolen employee credential and breaching the network without credentials in a more difficult test.

In its report titled ‘The Offensive Frontier: AI as the Attacker,’ Booz Allen identified that sophisticated cyberattacks are becoming increasingly accessible as the cost, time, and expertise required to launch advanced attacks collapse. Capabilities once limited to nation-states and highly sophisticated actors are now becoming available to criminal and non-state actors on demand.

It also found that critical infrastructure remains exposed today. The report calls for enforceable, sector-specific deadlines requiring operators to demonstrate readiness against AI-enabled attacks, helping ensure the U.S. and its critical organizations can harness AI faster and more effectively than adversaries. The unit of risk is no longer the individual model but the system as a whole. When paired with attack harnesses, tools, memory, and autonomy that guide its actions, even models short of the frontier can cause significant real-world harm.

The report also flagged that counter AI converts autonomy from an advantage into a liability. The same autonomy that gives AI attackers an edge creates vulnerabilities that defenders can exploit by disrupting how autonomous systems see, trust, and act, thereby slowing attacks and regaining critical action time. In Booz Allen testing, coordinated Counter AI playbooks reduced autonomous attacker success by more than 95%.

To help organizations defend against these emerging threats, Booz Allen introduced Vellox Labs Guile, a Counter AI product designed to disrupt autonomous attacks by shaping what AI attackers see and trust, degrading their ability to execute an attack. As autonomous threats advance, Guile adapts, learning from real threats and leveraging the latest frontier AI models to evolve its defenses in real time and safeguard critical assets.

Booz Allen said most models could reach full autonomous kill-chain capability within six months, potentially compressing attack timelines and reducing response window for organizations, including critical infrastructure operators, that depend on human-led detection and containment. The testing also found that autonomous offensive capabilities are emerging across a broader range of AI models. About two-thirds of the models reliably gained initial access to a defended network without credentials, while models demonstrated capabilities including vulnerability identification, exploit creation and lateral movement. 

The report also revealed that the U.S. must move now to create and sustain cyber overmatch. That means accelerating machine-speed and counter-AI defense, putting critical infrastructure on a binding readiness clock, and continuously measuring global AI capability before adversaries operationalize these capabilities at scale.

Testing reveals a cyber landscape far more capable and nuanced than headline benchmark scores suggest. AI models are already demonstrating meaningful offensive capabilities, but their real-world impact depends heavily on the vulnerabilities they face and the systems built around them. Leading frontier models like Claude Mythos can autonomously execute the full cyber kill chain, though real-world vulnerability discovery remains a major dividing line. 

While performance on intentionally introduced vulnerabilities was broad across U.S., Chinese, open, and closed models, every frontier API model tested scored zero against actual vulnerabilities. This concentration of capability creates a national security imperative to protect advanced models and prevent their highest-risk cyber capabilities from being operationalized by adversaries, while creating a defensive window since real-world offensive capability still trails benchmark performance.

Cyber capability extends well beyond leading frontier models and is not country-specific. Roughly two-thirds of the models tested reliably gained initial access to a defended network, and capability is not equal across models, with leading Chinese models still trailing the frontier. However, the remaining gap may be an engineering problem rather than an AI capability problem, as relatively simple supporting software can close capability gaps for less-capable models. Organizations must assess the full AI system rather than the model in isolation, because inexpensive, widely available engineering can amplify model capabilities.

Attack harnesses matter as much as or more than the model itself by connecting AI to the tools, memory, feedback, and execution environment needed to stay focused, adapt, and chain actions into sustained operations. When paired with an attack harness, less capable models can rival frontier performance, and configuration dramatically affects model behavior. The same model given identical tasks may refuse under one framing but comply under another, meaning AI safeguards are not fixed properties but shift with context and configuration. Organizations must continuously test guardrails under real-world conditions rather than assume refusals in one setting will hold in another.

The most dangerous AI-cyber capabilities may be beyond U.S. regulatory reach and invisible to traditional evaluations, as model benchmarks measure individual models rather than full systems paired with tools and autonomy. 

Foreign models that adversaries could deploy against U.S. infrastructure may sit largely beyond U.S. jurisdiction, meaning the U.S. may neither control nor fully understand the capabilities it could face. The stronger defense becomes resilience through measuring real-world capability, hardening critical systems, accelerating AI-enabled defense, and preparing for threats regardless of model origin or control. 

Strategic opportunity lies in mastering agentic AI on both offense and defense, aggressively developing capabilities that accelerate authorized cyber operations while simultaneously building AI-enabled defenses that detect, decide, and respond at machine speed, giving the United States the ability to impose costs on adversaries while making U.S. systems faster to defend and more resilient when attacked.

Booz Allen observes that the U.S. is not yet prepared for the speed and scale of increasingly capable AI-enabled cyberattacks. Foreign and open-weight models put much of this risk beyond the reach of U.S. regulation, demanding an urgent, coordinated response across government and industry. AI-enabled attacks are no longer a distant threat; their exponential trajectory and impact are inevitable unless immediate and effective action is taken. A rapidly closing window exists to strengthen U.S. defenses before today’s remaining capability gaps give adversaries a significant advantage.

“We recommend that enforceable, sector-specific deadlines be put in place for critical infrastructure to demonstrate resilience against AI-enabled attacks. Preparedness cannot remain an open-ended planning or compliance exercise,” according to the report. “CISA and sector risk management agencies should establish minimum performance standards, implementation milestones, remediation deadlines, and recurring exercises that assume adversaries can use AI to accelerate reconnaissance, credential discovery, privilege escalation, lateral movement, exploit adaptation, and vulnerability research. Critical infrastructure should demonstrate that it can contain an AI-enabled intrusion while sustaining essential services.”

Booz Allen outlined that binding, sector-specific AI-cyber readiness standards must be established and kept current across energy, communications, financial services, water, healthcare, and other critical sectors. These standards should define the capabilities each sector must demonstrate, with clear implementation and remediation deadlines. 

Frontier-model providers supporting sensitive environments should be required to provide standardized diagnostics demonstrating cyber capability, sensitivity to configuration and instructions, and the cost and compute required for consequential cyber tasks, ensuring defensive requirements evolve as AI capabilities advance.

Critical infrastructure organizations must prove readiness against realistic AI-enabled attacks through instrumented exercises using current AI capabilities, with independent validation and deadlines to remediate material weaknesses. Executives should be held accountable for demonstrated resilience rather than simply compliance on paper, shifting organizational culture toward actual defensive capability rather than procedural compliance.

Critical infrastructure must be designed to contain compromise, not just prevent it. Organizations should accelerate zero trust architecture, network segmentation, least-privilege access, strong identity controls, and isolation of high-value assets to limit blast radius when breaches occur. The defensive standard should assume that AI-enabled attackers may gain initial access and focus instead on whether organizations can contain them, protect critical functions, and prevent a foothold from becoming a system-wide compromise that undermines essential services.

In conclusion, Booz Allen recognizes that AI-enabled cyberattacks are no longer theoretical—autonomous AI agents are moving from research into real-world operations, compressing the time required to plan, adapt, and execute attacks and shifting cyber economics toward attackers. The pace of change is now measured in days and weeks rather than years, making speed the new currency of cyber advantage. 

The U.S. has an opportunity to create cyber overmatch by mastering agentic AI on both offense and defense, using it to increase the speed, scale, and effectiveness of authorized operations while building defenses capable of detecting, deciding, and responding at machine speed. Organizations must also defend against a new class of risk: autonomous agents that take unintended paths, bypass controls, or continue operating beyond user anticipation.

Cyber capability will never again be less advanced than it is today, as every generation of models, agents, and harnesses will raise the ceiling and lower the expertise required to reach it. The organizations and nations that gain advantage will not simply be those with the most AI but those that adapt their offensive and defensive cyber operations faster and more effectively than their adversaries. 

Fully autonomous cyber operations are no longer hypothetical, with one frontier model already demonstrating meaningful end-to-end autonomous execution and limited offensive capability creation, while a much broader global fleet of U.S. and Chinese closed- and open-weight models advances rapidly through the same lifecycle. The timing of the next capability threshold is uncertain, but the direction is clear.

“The United States can and should govern frontier systems within its reach. But it cannot regulate its way to cyber advantage. Foreign and open-weight models will remain available to determined adversaries,” according to the report. “The national response must therefore extend across government and the private sector: continuously measure the global capability landscape, accelerate AI-enabled defense, put critical infrastructure on a binding readiness clock, and preserve the ability of U.S. operators and defenders to develop, test, and deploy advanced capabilities.” 

It added that the objective should be sustained cyber overmatch, ensuring the U.S. and the organizations that underpin its economy and national security can harness AI faster, defend against it more effectively, and adapt before adversaries do.

Last week, OpenAI and various technology and cybersecurity organizations launched a collective cyber defense initiative calling for coordinated global efforts to protect essential services, including hospitals, water treatment plants, and internet infrastructure, against increasingly sophisticated AI-enabled attacks. While these organizations face growing risks, longstanding vulnerabilities such as unpatched software, misconfigurations, weak authentication, and legacy technical debt continue to leave systems exposed.



Source link